SVC—04 · EXERCISE

Red team and adversary emulation

A time-boxed, threat-informed exercise with deconfliction, stop conditions, and evidence of executed, prevented, and detected behaviors.

Start scoping
MITRE ATT&CK 19.1NIST SP 800-115PTES

TEST BOUNDARY

What sits inside the boundary

Business objective, target flags and relevant threat model
Permitted initial access, TTPs, channels and target environments
White-cell coordination, safety controls and emergency stop

ACCESS MODES

Knowledge level is scoped

External objective
Assumed breach
Hybrid campaign

DELIVERY—LEDGER

Deliverables you can inspect.

OUTPUT

Objective and attack-chain narrative

Executed, detected, and prevented behavior record

Purple-team debrief and control improvements

EFFORT—DRIVER

Objectives, duration and team composition

Permitted techniques and initial-access assumptions

Geography, on-site work and deconfliction

EXPLICIT—LIMIT

ATT&CK mapping is not a promise of complete coverage

Social, physical, and persistence actions require explicit scenario authorization

POINT—IN—TIME

Precision includes what we do not claim.

A penetration test provides evidence about named assets, versions, access, and time. It does not guarantee the absence of vulnerabilities, replace internal vulnerability management, or constitute compliance certification.

Method and limitations

SCOPE—NEXT

Define the boundary before the fee.

Build a scope draft